Your Shredded Visa Card May Still Work at the Checkout
Overview
Researchers from UMass Amherst have discovered a serious flaw in Visa's EMV payment system that allows expired contactless cards to make real purchases. By exploiting an unsigned expiry field in the card's EMV kernel, the team demonstrated that these expired cards could be used for transactions at actual retail and grocery stores. This raises significant concerns for consumers and merchants alike, as it means that cards which should no longer be valid can still facilitate payments. The potential for fraud is alarming, especially since many users may not be aware that their expired cards could still be functional. This incident highlights the urgent need for Visa and other financial institutions to address security vulnerabilities in their payment systems to protect users from unauthorized transactions.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Visa contactless credit cards
- Action Required: Visa should implement security updates to address the unsigned expiry field in the EMV kernel and ensure expired cards cannot be used for transactions.
- Timeline: Disclosed at USENIX Security 2026
Original Article Summary
UMass Amherst researchers showed expired Visa contactless cards can make real purchases by exploiting an unsigned expiry field in Visa’s EMV kernel. Researchers at the University of Massachusetts Amherst demonstrated at USENIX Security 2026 in Baltimore that expired Visa contactless credit cards can complete real purchases, including transactions at live retail and grocery merchants, by […]
Impact
Visa contactless credit cards
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Disclosed at USENIX Security 2026
Remediation
Visa should implement security updates to address the unsigned expiry field in the EMV kernel and ensure expired cards cannot be used for transactions.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.